AOSSIE-Org / AOSSIE-Org/Devr.AI

BUG: Make repository indexing read-only (avoid dependency installs during static analysis)

未關閉
#237 2 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
Python
星號
102
分支
137
PR 合併指標
30 天內沒有已合併 PR

描述

### Is there an existing issue for this?

- [x] I have searched the existing issues

### What happened?

## 📌 Issue Overview
While working with the repository indexer, I noticed that indexing a codebase can unintentionally install dependencies and mutate the cloned repository’s environment. This makes indexing non-deterministic and breaks the expectation that indexing is a read-only operation.

## 🔍 Steps to Reproduce
1. Go to the Discord server
2. Run` /index_repository AOSSIE-Org/Devr.AI`
3. Observe the indexing process in the Falkor backend logs

## 🎯 Expected Behavior
1. Indexing is deterministic and read-only
2. No virtual environments or package installs are triggered
3. Static indexing works without dependency metadata
4. Dependency analysis can be explicitly enabled later if needed

## 🚨 Actual Behavior
When indexing a Python repository:
1. `venv/` directories can be created inside the cloned repo
2. Dependencies like `tree-sitter`, `multilspy`, and `sentence-transformers` may get installed
3. Indexing can remain stuck in a pending state
4. Additionally, attempting to delete a failed index returns an error (“Failed to delete graph from backend”), leaving the system in a stuck state.

This behavior occurs even when:
1. LSP is disabled
2. Poetry is disabled
3. The intent is static (AST-only) analysis

## 📷 Screenshot
#### On Discord:

Image

#### Terminal
```bash
backend/api/repositories/Devr.AI/venv/lib/python3.10/site-packages/discord/types/role.py over existing file
Installing /home/tanisha/Devr.AI/backend/app/database/falkor/code-graph-backend/api/repositories/Devr.AI/venv/lib/python3.10/site-packages/discord/types/snowflake.py over existing file
Installing /home/tanisha/Devr.AI/backend/app/database/falkor/code-graph-backend/api/repositories/Devr.AI/venv/lib/python3.10/site-packages/discord/types/sticker.py over existing file
Installing /home/tanisha/Devr.AI/backend/app/database/falkor/code-graph-backend/api/repositories/Devr.AI/venv/lib/python3.10/site-packages/discord/types/team.py over existing file
Installing /home/tanisha/Devr.AI/backend/app/database/falkor/code-graph-backend/api/repositories/Devr.AI/venv/lib/python3.10/site-packages/discord/types/template.py over existing file
Installing /home/tanisha/Devr.AI/backend/app/database/falkor/code-graph-backend/api/repositories/Devr.AI/venv/lib/python3.10/site-packages/discord/types/widget.py over existing file
Installing /home/tanisha/Devr.AI/backend/app/database/falkor/code-graph-backend/api/repositories/Devr.AI/venv/lib/python3.10/site-packages/discord/ui/__init__.py over existing file
Installing /home/tanisha/Devr.AI/backend/app/database/falkor/code-graph-backend/api/repositories/Devr.AI/venv/lib/python3.10/site-packages/discord/ui/button.py over existing file
Installing /home/tanisha/Devr.AI/backend/app/database/falkor/code-graph-backend/api/repositories/Devr.AI/venv/lib/python3.10/site-packages/discord/ui/item.py over existing file
.
.
ERROR:code_graph:Error adding dependencies: 'NoneType' object is not iterable
INFO:root:Processing file (1/168): /home/tanisha/Devr.AI/backend/app/database/falkor/code-graph-backend/api/repositories/Devr.AI/backend/routes.py
INFO:werkzeug:127.0.0.1 - - [14/Jan/2026 01:10:27] "POST /analyze_repo HTTP/1.1" 500 -
```
#### Evidence (Indexing Mutates Environment)

1. A venv/ directory is created inside the cloned repository
2. Python dependencies are installed into that environment
3. Existing files under site-packages/ are overwritten
4. Indexing eventually fails with a dependency-related error

## 💡 Suggested Improvements
1. Disables dependency resolution by default during indexing
2. Introduces a static_only mode for analyzers
3. Separates code graph (AST) generation from dependency graph resolution
4. Ensures indexing never installs packages or modifies the filesystem

### Record

- [x] I agree to follow this project's Code of Conduct
- [x] I want to work on this issue

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。